EU AI Act compliance

Overview

This page describes how TrackMe’s AI capabilities position against Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act (“AI Act”). It is written for compliance, risk and legal teams that need to answer one question quickly — “can we use TrackMe’s AI features in the EU, and what does the AI Act require from us if we do?” — and for TrackMe administrators who want to understand what the product already does for them.

It complements AI Compliance, Privacy and Data Governance (privacy, data flows, tool inventory, guardrails) and Auditing AI activity (audit trail): those pages describe how the product behaves; this page maps that behaviour to the AI Act’s roles, risk categories and obligations.

Note

This page reflects TrackMe Limited’s good-faith self-assessment of the product as implemented, and is provided for information only — it is not legal advice. The AI Act’s application always depends on your deployment context and use; organisations subject to the Act should perform their own assessment with qualified counsel.

Important

The short version — TrackMe Limited assesses TrackMe’s AI layer, for its intended purpose, as performing none of the Act’s prohibited practices and as falling outside both high-risk routes (the Annex III use-case list and the Annex I product-safety route). The operative obligations are therefore the Article 50 transparency duties — a formal AI Act category of its own, not an exemption: users must know when they interact with AI, and AI-generated content must be identifiable as such, by machines as well as humans. TrackMe implements both: every AI surface is explicitly labelled, and artefacts embedding LLM-generated content carry a machine-readable marking (see Article 50 transparency — how TrackMe complies).

Roles under the AI Act

The AI Act assigns obligations by role. A TrackMe deployment involves three:

AI Act role

Who

What it means

GPAI model provider

The entity that developed the model you configure and placed it on the market under its own name — OpenAI, Anthropic, Microsoft (Azure OpenAI), Google, Mistral, Splunk, or the upstream developer of a self-hosted model served via Ollama or a private OpenAI-compatible endpoint

The general-purpose AI model obligations of the Act (Articles 53/55 — model documentation, copyright policy, systemic-risk measures) sit with the model provider, not with TrackMe and not with you as a TrackMe user. Simply configuring — or self-hosting — a model does not make your organisation the model provider: you remain a deployer unless you develop or substantially modify a model, or place one on the market under your own name or trademark. Your agreement with the provider governs data use; see AI Compliance, Privacy and Data Governance.

AI system provider

TrackMe Limited

TrackMe integrates general-purpose models into an AI system with a defined intended purpose (Splunk data-monitoring assistance) and places it on the market. TrackMe Limited therefore treats itself as the provider of that AI system and owns the system-level transparency design described on this page.

Deployer

Your organisation, when you enable the AI layer

Deployers use an AI system under their own authority. Your obligations are limited in TrackMe’s risk category — see What you should do as a deployer below.

Risk classification

The AI Act is risk-tiered. TrackMe’s AI capabilities assess as follows:

AI Act category

Applies?

Rationale

Prohibited practices (Article 5)

No

TrackMe’s AI performs none of the banned practices: no manipulation or exploitation of persons, no social scoring, no biometric identification or categorisation, no emotion recognition. Its intended purpose is Splunk data-monitoring assistance; the exact data exchanged with the LLM per feature — including user-typed chat messages and, for FQM, sampled event excerpts — is documented feature-by-feature in AI Compliance, Privacy and Data Governance.

High-risk systems (Article 6 — Annex I and Annex III routes)

No

Neither of the Act’s two high-risk routes applies. Annex I route (Article 6(1)): TrackMe is not a product — nor a safety component of a product — covered by the Annex I Union product-safety legislation (machinery, medical devices, vehicles, etc.). Annex III route (Article 6(2)): IT observability is not an Annex III domain. The closest category — AI used as a safety component in the management and operation of critical digital infrastructure — does not apply: TrackMe observes and alerts, it does not operate or control infrastructure, and the AI layer is an advisory surface on top of TrackMe’s deterministic monitoring engine (detection, scoring and alerting are conventional code and remain fully functional with AI disabled). AI write actions target TrackMe’s own monitoring configuration and are RBAC-checked, consented and audited; AI Routines can additionally trigger operator-configured Splunk alert actions and external MCP tools — each individually and explicitly consented at routine creation — see AI Compliance, Privacy and Data Governance.

Transparency-risk systems (Article 50)

Yes

TrackMe’s AI Assistant interacts directly with users, and several features generate synthetic text (status reports, advisor summaries, routine notifications). The Article 50 transparency obligations are the operative requirements — fully addressed below.

General-purpose AI models (Chapter V)

Not TrackMe

TrackMe does not provide, train, or fine-tune any model. Model-level obligations rest with the model provider you select.

Article 50 transparency — how TrackMe complies

Article 50 (applicable since 2 August 2026) contains the two obligations relevant to TrackMe.

Disclosure of AI interaction — Article 50(1)

Persons interacting with an AI system must be informed they are interacting with AI, unless obvious from context. In TrackMe:

  • Every conversational surface is explicitly and persistently branded AI Assistant; assistant messages are labelled as such in the chat transcript.

  • Every agentic surface (AI Advisors, AI Concierge, AI Routines) is presented under an explicit AI name, launched from clearly-labelled entry points, and — for any write action — gated by an explicit consent flow (see AI Compliance, Privacy and Data Governance).

  • The entire AI layer is opt-in: nothing AI-related is shown to end users until an administrator configures a provider, so no user can encounter AI output unknowingly.

  • Disclosure is effective from the first interaction, as Article 50(5) requires: the AI Assistant panel is branded before any message is exchanged, the labelling is persistent (not a dismissible one-time notice), and it is rendered as clear, distinguishable text within the standard Splunk UI (theme-aware, keyboard-accessible) rather than hidden in tooltips or fine print.

Machine-readable marking of AI-generated content — Article 50(2)

Providers of AI systems generating synthetic content must ensure outputs are marked as artificially generated in a machine-readable format, in addition to any human-readable labelling. TrackMe applies machine-readable marking to artefacts that leave the product with embedded LLM content (the email surfaces below), and provenance labelling to AI result records stored in your Splunk indexes:

AI output surface

Marking

Stateful alert emails with an AI status report (ai_status_report=1)

The message carries an X-TrackMe-AI-Generated: true MIME header; the HTML section holding the report carries a data-ai-generated="true" attribute; the plain-text alternative labels the section --- AI Status Report (AI-generated content) --- (TrackMe 2.4.13+). Emails without an AI report carry no marking — the signal is meaningful precisely because it is not blanket-applied.

AI Routine notification emails

The notification body is the LLM-generated run summary, so every routine email carries the same X-TrackMe-AI-Generated: true header and data-ai-generated="true" HTML attribute (TrackMe 2.4.13+).

AI Routine Splunk event notifications

Routine splunk_event deliveries index the AI-authored summary / evidence under the dedicated trackme:ai:routines sourcetype (event source = the routine id), so these records are identifiable as AI output in plain SPL — provenance labelling, like the advisor results below. The email variant of the same notification carries the full email marking above.

Advisor / agent results indexed in Splunk

Every automated or interactive agent run is indexed with a dedicated trackme:ai_agent:<advisor>:<mode> sourcetype, so stored agent results are identifiable — and filterable — as AI output in plain SPL. These sourcetypes are provenance labelling of the stored result records (they double as the audit trail, see Auditing AI activity); the artefact-level Article 50(2) marking for content that leaves the product is the email marking above.

Interactive chat responses

Rendered exclusively inside the persistently-labelled AI Assistant panel — an Article 50(1) interaction surface where the AI origin of every response is disclosed by construction. The product does not itself embed chat output into distributable artefacts; where TrackMe embeds LLM output into an artefact that leaves the product (the email surfaces above), it applies the machine-readable marking. TrackMe tracks the Commission’s transparency guidelines and the Code of Practice on marking of AI-generated content as they mature, and will extend marking mechanisms accordingly.

Deterministic notifications (Configuration Guardian, topology alerts, connectivity test emails, standard alert emails without an AI report)

Never marked — these contain no LLM-generated content. TrackMe deliberately excludes them so the marking remains a reliable discriminator for downstream mail rules, DLP and compliance tooling.

Note

Article 50(2) expects markings to be effective, interoperable, robust and reliable as far as technically feasible, reflecting the state of the art. The X-TrackMe-AI-Generated header and data-ai-generated attribute are TrackMe’s current product marking, aligned with Article 50(2)’s direction for email artefacts; as the Commission’s guidelines and the Code of Practice on marking of AI-generated content converge on common mechanisms, TrackMe will evolve its markings accordingly (the same commitment stated for the chat surface above). Deployers should not assume the proprietary header alone survives every mail transformation — see the transparency-chain guidance in What you should do as a deployer.

Alignment with the Act’s broader principles

Beyond its formal obligations, TrackMe’s AI design already implements the practices the AI Act promotes for all AI systems:

AI Act principle

TrackMe implementation

Human oversight

Read-only inspect mode versus consented act mode on every advisor; explicit per-run consent cards; per-tenant enablement flags; per-model opt-outs; a global administrator kill switch (enable_ai_assistant). See AI Compliance, Privacy and Data Governance.

Transparency of operation

Structured results with reasoning traces; live tool-call progress feeds; every tool an agent may use is publicly documented in the complete tool inventory of AI Compliance, Privacy and Data Governance.

Traceability / record-keeping

Every AI interaction and every agent action is recorded in the per-entity audit trail and in dedicated audit dashboards, with structured audit events in your own Splunk indexes. See Auditing AI activity.

Robustness

The AI layer is fail-open by design: an AI failure never blocks monitoring, alerting or email delivery. LLM output is treated as untrusted input (sanitised and escaped before rendering).

Privacy and data governance

Direct search-head-to-provider data path with no vendor intermediary, self-hosted / air-gapped options, optional anonymisation of entity and index names, no training on your data by TrackMe. See AI Compliance, Privacy and Data Governance.

Applicability timeline

Date

Milestone

2 February 2025

The Act’s original core prohibited-practices ban (Article 5) and the AI-literacy obligation (Article 4) apply. (No impact: TrackMe performs no prohibited practice.)

2 August 2025

General-purpose AI model obligations apply — to model providers, not TrackMe.

27 July 2026

The “digital omnibus on AI” amendment — Regulation (EU) 2026/1744 — enters into force: it adds a new Article 5 prohibition (non-consensual intimate imagery / CSAM generation, applicable 2 December 2026) (not relevant to TrackMe), defers Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028 (TrackMe is neither), and keeps the 2 August 2026 Article 50 application date — while adding, via the new Article 111(4), the four-month transitional period for the Article 50(2) machine-readable marking on systems already on the market (next-but-one row).

2 August 2026

Article 50 transparency obligations apply — the operative requirements for TrackMe, addressed as described on this page.

2 December 2026

End of the transitional grace period for the machine-readable marking obligation for AI systems placed on the market before 2 August 2026. TrackMe ships the marking from 2.4.13, ahead of this deadline.

What you should do as a deployer

For a system in TrackMe’s risk category, deployer obligations are narrower than for high-risk systems, but they are real. The following covers what applies (and what is good practice):

  • AI literacy (Article 4) — ensure staff operating TrackMe’s AI features have a sufficient understanding of what the AI does and its limits. The Artificial Intelligence in TrackMe and AI Compliance, Privacy and Data Governance pages are written to support exactly this.

  • Article 50(4) disclosure triggers — deployers must clearly disclose (i) deep fakes (AI-generated or manipulated image, audio or video presented as authentic) and (ii) AI-generated or manipulated text published to inform the public on matters of public interest (unless the text underwent human review and a person holds editorial responsibility). TrackMe produces neither: its AI output is operational monitoring text delivered to your own teams. The obligation would only be triggered by your downstream use — for example, publishing an AI-generated TrackMe report verbatim as public communication — in which case disclose accordingly.

  • Keep the transparency chain intact — if you forward or re-publish AI-generated content (e.g. pasting an AI status report into a ticket or report), preserve its AI-generated labelling. Note that preservation is conditional on the path: forwarding as an attachment preserves the X-TrackMe-AI-Generated header, but inline forwards typically re-compose the message and may drop custom headers (the in-body data-ai-generated attribute and the plain-text section label are more likely to survive). When a republication path strips the marking, re-apply an equivalent AI-generated label yourself.

  • Review your model provider’s terms — data-use, residency and retention are governed by your agreement with the provider you configure; see AI Compliance, Privacy and Data Governance for provider-specific notes and self-hosted options.

  • Use the audit surfaces — the audit dashboards and trackme:ai_agent:* events give you the record-keeping evidence an AI governance programme typically asks for; see Auditing AI activity.

  • Run your own assessment — if your organisation uses TrackMe in an unusual context (for example, as part of a system that does fall under Annex III), assess that composed system yourself; TrackMe’s classification above covers the product as shipped.

Version applicability

The Article 50(2) machine-readable email marking ships in the companion TrackMe 2.4.13 application release; it will appear in the Version 2.4.13 entry of the release notes when that release is published. All other mechanisms referenced on this page (labelled AI surfaces, consent flows, audit trail, indexed trackme:ai_agent:* and trackme:ai:routines events, kill switch, anonymisation) are available from TrackMe 2.4.x as described in AI Compliance, Privacy and Data Governance.